Print Download PDF Send Feedback

Previous

Next

Default Configuration of CoreXL

When you enable CoreXL, the default number of CoreXL Firewall instances is based on the total number of CPU cores.

The default affinity setting for all interfaces is automatic when SecureXL is enabled. See Allocation of Processing CPU Cores.

Traffic from all interfaces is directed to the CPU cores that run the CoreXL Secure Network Distributor (SND).

Default number of IPv4 CoreXL Firewall instances:

Number of
CPU cores

Default number of
CoreXL IPv4
FW instances

Default number of
Secure Network
Distributors (SNDs)

1

1 (CoreXL is disabled)

1 (CoreXL is disabled)

2

2

2

4

3

1

6-20

Number of CPU cores, minus 2

2

More than 20

Number of CPU cores, minus 4.
However, no more than 40.

4

The numbers of CoreXL Firewall instances start from zero.

The numbers of CPU cores start from the highest CPU ID allowed by the current Check Point license on your Security Gateway.

Refer to the ID and CPU columns in this example:

fw ctl multik stat

 

ID | Active | CPU | Connections | Peak

----------------------------------------------

0 | Yes | 7 | 5 | 21

1 | Yes | 6 | 3 | 23

2 | Yes | 5 | 5 | 25

3 | Yes | 4 | 4 | 21

4 | Yes | 3 | 5 | 21

5 | Yes | 2 | 5 | 20

 

fw6 ctl multik stat

ID | Active | CPU | Connections | Peak

----------------------------------------------

0 | Yes | 7 | 0 | 4

1 | Yes | 6 | 0 | 4

Maximal number of IPv4 CoreXL Firewall instances:

Gaia kernel edition

Check Point Appliance

Open Server

64-bit

40

40

Notes: